Mixed Deck — All CCCP Topics Flashcards
100 cards from real CCCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 20 Mixed Deck — All CCCP Topics flashcards as text
What is the purpose of regulatory frameworks?
Answer: To provide a structure for lawful business conduct
Regulatory frameworks are established sets of rules, laws, and guidelines designed to govern specific industries or activities. Their purpose is to provide a clear structure that ensures businesses operate lawfully, ethically, and responsibly, protecting consumers, the environment, and fair competition. These frameworks help prevent misconduct and maintain public trust.
Which of the following is an example of a 'detective' rather than a 'preventive' internal control?
Answer: Conducting monthly bank reconciliations
Monthly bank reconciliations detect discrepancies that have already occurred, making them a detective control, whereas the other options prevent problems before they happen.
Which of the following best describes 'inherent risk' in a compliance context?
Answer: Risk that exists before any mitigating controls are in place
Inherent risk is the raw or gross risk level existing in a business process or activity before any controls or mitigation measures are applied.
A Business Associate Agreement (BAA) under HIPAA must include which of the following provisions?
Answer: Obligations of the BA to report breaches of unsecured PHI to the covered entity
BAAs must require business associates to report any discovered breach of unsecured PHI to the covered entity within applicable timeframes.
Under the Three Lines of Defense model, which line is responsible for setting risk appetite and overseeing the overall risk management framework?
Answer: Board and senior management
The board and senior management sit above the three lines and are responsible for establishing risk appetite and providing overall governance of the risk framework.
Under the Federal Sentencing Guidelines, what factor can REDUCE an organization's culpability score if it has an effective compliance program?
Answer: Self-reporting, cooperation, and acceptance of responsibility
Self-reporting violations to authorities, cooperating with investigations, and accepting responsibility are factors that reduce an organization's culpability score under the Federal Sentencing Guidelines.
Which of the following best describes the 'cooperation credit' framework under the USAM (United States Attorneys' Manual)?
Answer: A discretionary credit rewarding companies that assist the government by disclosing facts and identifying responsible individuals
Cooperation credit under the USAM is discretionary and depends on the quality and timeliness of the company's assistance, including disclosure of facts about culpable individuals.
What is the purpose of risk assessment?
Answer: To evaluate risk likelihood and impact
Risk assessment is the systematic process of identifying potential risks, analyzing their probability of occurrence (likelihood), and determining the severity of their potential consequences (impact). This evaluation helps organizations prioritize risks, understand their exposure, and make informed decisions about which risks require the most attention and resources for mitigation. It forms the basis for effective risk management strategies.
What role does 'values-based compliance' play alongside 'rules-based compliance' in a CCCP framework?
Answer: Values-based compliance motivates ethical behavior from internal principles, complementing rule-based deterrence
Values-based compliance builds intrinsic motivation for ethical behavior, while rules-based compliance provides clear boundaries — together they create a more resilient program.
When benchmarking a compliance program's effectiveness against peers, which source provides the most authoritative industry standards?
Answer: DOJ/SEC guidance documents and industry association surveys
DOJ/SEC guidance and industry surveys (e.g., SCCE, ECI) provide validated external benchmarks for measuring program maturity.
A compliance officer is designing a new training program. Which approach is generally considered MOST effective for adult learners?
Answer: Scenario-based, role-specific training delivered in shorter, frequent sessions
Adult learning research supports scenario-based, role-specific instruction in shorter sessions ('microlearning') as more effective than infrequent, comprehensive lectures.
The 'tone at the top' concept in corporate governance primarily refers to:
Answer: Senior leadership's visible commitment to ethical conduct and compliance
Tone at the top reflects the ethical culture set by senior leaders through their words, actions, and decision-making priorities.
Which scenario BEST illustrates 'willful blindness' in a corporate compliance context?
Answer: An executive who deliberately avoids learning about potential misconduct to maintain plausible deniability
Willful blindness—deliberately avoiding knowledge of wrongdoing to claim ignorance—is treated by courts similarly to actual knowledge and does not shield executives from liability.
During integration planning, a compliance officer identifies that the target uses a third-party vendor flagged in a prior sanctions screening. What is the correct compliance response?
Answer: Conduct enhanced due diligence and escalate to OFAC counsel before continuing the relationship
Sanctions-flagged vendors require enhanced due diligence and OFAC counsel review before any decision is made to continue, modify, or terminate the relationship.
Which factor most significantly elevates the compliance risk associated with a foreign third-party agent?
Answer: The agent operates in a high-corruption-index country and interacts with foreign government officials
A foreign agent who interacts with government officials in a high-corruption environment is a classic FCPA risk scenario requiring enhanced due diligence.
Which metric is most useful for measuring the effectiveness of an ethics and Code of Conduct program?
Answer: Combination of hotline utilization rates, substantiation rates, repeat violations, and employee survey data
Effective measurement combines multiple data points — hotline usage, substantiation rates, recidivism, and survey sentiment — to assess true program health.
Which type of assessment involves compliance staff independently testing whether business unit controls are operating as designed?
Answer: Second-line compliance monitoring and testing
Second-line compliance monitoring involves the compliance function independently testing controls, separate from business unit self-assessment.
A compliance officer discovers that the target company has an undisclosed FCPA investigation during due diligence. What is the most appropriate immediate action?
Answer: Notify deal counsel and senior leadership to assess materiality and deal impact
Undisclosed government investigations are material findings that must be escalated to legal counsel and leadership to evaluate risk and renegotiate terms if needed.
What is the compliance officer's role in an ethics hotline program?
Answer: To ensure the hotline is accessible, confidential, and that reports are properly triaged and investigated
The compliance officer ensures the hotline is operational, confidential, non-retaliatory, and that all reports receive appropriate follow-up and investigation.
A board member asks why the compliance budget increased 30% year over year. The BEST response from the CCO includes:
Answer: Specific drivers such as new regulations, headcount additions, technology investments, and cost-benefit outcomes
Boards expect compliance spending to be justified with specific drivers and demonstrated value, not general references to complexity.